{"cve":"CVE-2026-60572","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[12.2.3,12.2.15]"}}],"enrichment":{"confidence":100.0,"confidence_source":"manual","scores":[{"score":100.0,"source":"manual"}]},"original":{"product":"Oracle E-Business Suite Integrated SOA Gateway","source":"cna","vendor":"Oracle Corporation"},"product":"e-business_suite_integrated_soa_gateway","vendor":"oracle"}],"created":"2026-07-23T20:39:01.961624+00:00","title":"Unauthorized Data Modification and Partial Denial via Improper Authority Control in Oracle E‑Business Suite Integrated SOA Gateway","updated":"2026-08-04T17:15:03.010731+00:00","vendors":["oracle","oracle$PRODUCT$e-business_suite_integrated_soa_gateway"]},"epss":{"score":0.00262},"mitre":{"cpes":["cpe:2.3:a:oracle:e-business_suite_integrated_soa_gateway:*:*:*:*:*:*:*:*"],"created":"2026-07-21T21:35:56.299000+00:00","description":"Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Integrated SOA Gateway.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle E-Business Suite Integrated SOA Gateway accessible data as well as  unauthorized read access to a subset of Oracle E-Business Suite Integrated SOA Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle E-Business Suite Integrated SOA Gateway. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/60xxx/CVE-2026-60572.json","references":["https://www.oracle.com/security-alerts/cpujul2026.html"],"title":null,"updated":"2026-07-27T15:13:29.323000+00:00","vendors":["oracle","oracle$PRODUCT$e-business_suite_integrated_soa_gateway"],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*"],"created":"2026-07-21T22:17:57.487000+00:00","description":"Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Integrated SOA Gateway.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle E-Business Suite Integrated SOA Gateway accessible data as well as  unauthorized read access to a subset of Oracle E-Business Suite Integrated SOA Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle E-Business Suite Integrated SOA Gateway. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-60572.json","references":["https://www.oracle.com/security-alerts/cpujul2026.html"],"title":null,"updated":"2026-08-06T14:54:49.320000+00:00","vendors":["oracle","oracle$PRODUCT$e-business_suite"],"weaknesses":["CWE-284"]},"opencve":{"changes":[{"created":"2026-07-21T22:00:00+00:00","data":[{"details":{"new":"Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Integrated SOA Gateway.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle E-Business Suite Integrated SOA Gateway accessible data as well as  unauthorized read access to a subset of Oracle E-Business Suite Integrated SOA Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle E-Business Suite Integrated SOA Gateway. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$e-business_suite_integrated_soa_gateway"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:e-business_suite_integrated_soa_gateway:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$e-business_suite_integrated_soa_gateway"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cpujul2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"c9df819a-2785-485a-abbc-ca4ecb9e781b"},{"created":"2026-07-24T20:00:00+00:00","data":[{"details":{"new":"Low‑Privilege Remote Data Modification in Oracle E‑Business Suite Integrated SOA Gateway","old":null},"type":"title"},{"details":{"added":["CWE-284","CWE-862"],"removed":[]},"type":"weaknesses"}],"id":"33a96f7f-5dd8-462e-8487-b004d2ccbc2d"},{"created":"2026-07-27T16:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"2438d56c-420c-4354-997f-bee7a0000cc6"},{"created":"2026-08-01T06:00:00+00:00","data":[{"details":{"new":null,"old":"Low‑Privilege Remote Data Modification in Oracle E‑Business Suite Integrated SOA Gateway"},"type":"title"},{"details":{"added":[],"removed":["CWE-862"]},"type":"weaknesses"}],"id":"370d1efc-36f6-4e35-8ad0-a8a4cef8aec7"},{"created":"2026-08-04T17:30:00+00:00","data":[{"details":{"new":"Unauthorized Data Modification and Partial Denial via Improper Authority Control in Oracle E‑Business Suite Integrated SOA Gateway","old":null},"type":"title"}],"id":"b4d7bb61-3e74-4477-a8c4-e0cad8096dc8"}],"cpes":{"data":["cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*","cpe:2.3:a:oracle:e-business_suite_integrated_soa_gateway:*:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-07-21T21:35:56.299000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Integrated SOA Gateway.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle E-Business Suite Integrated SOA Gateway accessible data as well as  unauthorized read access to a subset of Oracle E-Business Suite Integrated SOA Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle E-Business Suite Integrated SOA Gateway. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00262},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cpujul2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Unauthorized Data Modification and Partial Denial via Improper Authority Control in Oracle E‑Business Suite Integrated SOA Gateway","provider":"enrichment"},"updated":{"data":"2026-08-04T17:15:03.010731+00:00","provider":"enrichment"},"vendors":{"data":["oracle","oracle$PRODUCT$e-business_suite","oracle$PRODUCT$e-business_suite_integrated_soa_gateway"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-284"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-07-21T21:35:56.299000+00:00","description":"Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Integrated SOA Gateway.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle E-Business Suite Integrated SOA Gateway accessible data as well as  unauthorized read access to a subset of Oracle E-Business Suite Integrated SOA Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle E-Business Suite Integrated SOA Gateway. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-07-27T15:13:11.504000+00:00","vendors":[],"vulnrichment_repo_path":"2026/60xxx/CVE-2026-60572.json","weaknesses":["CWE-284"]}}